CVE-2011-4514

CRITICAL

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced;...

Affects 5 products across 1 vendor.

BCS8.05
CVSS 2.010.0
EPSS3.5%
Percentile88th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The TELNET daemon in multiple Siemens WinCC products and SIMATIC HMI panels does not perform authentication, allowing remote attackers to gain unauthorized access via a TCP session. This vulnerability has a CVSS score of 10.0, indicating critical severity.

BSID: BS-2012-GLOBAL-089483-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2011-4514?
The TELNET daemon in multiple Siemens WinCC products and SIMATIC HMI panels does not perform authentication, allowing remote attackers to gain unauthorized access via a TCP session. This vulnerability has a CVSS score of 10.0, indicating critical severity.
What is the CVSS score for CVE-2011-4514?
CVE-2011-4514 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.5%.
Is CVE-2011-4514 actively exploited?
No confirmed active exploitation of CVE-2011-4514 as of 2026-05-30.
How do I remediate CVE-2011-4514?
Priority: IMMEDIATE.
What systems are affected by CVE-2011-4514?
CVE-2011-4514 affects: Siemens, Siemens, Siemens, Siemens, Siemens.
What NERC-CIP standard applies to CVE-2011-4514?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to the TELNET service without proper authentication, which could lead to the compromise of critical assets.
What IEC 62443 requirement maps to CVE-2011-4514?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a lack of authentication for a network service, which is a fundamental security requirement to prevent unauthorized access and control of industrial systems.
Vulnerability Details
CVE IDCVE-2011-4514
BSIDBS-2012-GLOBAL-089483-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2012-02-03
Last Modified2026-04-29
ICS Relevance80%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Remote attackers can exploit this vulnerability by establishing a TCP connection to the TELNET service on the affected devices. Since no authentication is required, the attacker can gain full control over the device, leading to potential data exfiltration, command execution, and system compromise.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Siemens Wincc Flexible
Siemens Wincc
Siemens Simatic Hmi Panels
Siemens Wincc Runtime Advanced
Siemens Wincc Flexible Runtime
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 5296 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation to isolate the affected systems from untrusted networks. Use firewalls to restrict access to the TELNET service only to trusted IP addresses.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to the TELNET service without proper authentication, which could lead to the compromise of critical assets.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a lack of authentication for a network service, which is a fundamental security requirement to prevent unauthorized access and control of industrial systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash4378b98e7e3afcb7ce0a00f708397e17bd837a3dbc2549d6a1680869876c814883068af226872afbdc009171d63c6b002c32ffec7254e63296b574689b35a93c
Related CVEs affecting Siemens
CVE-2026-56451 10.0 Siemens Opcenter X CVE-2008-6916 10.0 Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to... CVE-2000-0964 10.0 Buffer overflow in the web administration service for the HiNet LP5100 IP-pho... CVE-2007-1917 10.0 Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library... CVE-2025-40805 10.0 Affected devices do not properly enforce user authentication on specific API ...
View all Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →